Thirty days. No fee. One honest answer.
A free design-partner engagement, not a paid trial. Connect your identity provider in about fifteen minutes. See the AI your organisation is actually running on day one. Leave with systems mapped to the frameworks that reach you, a working release gate, and a record you can hand to an auditor.
- Free · design-partner track
- Read-only to start
- No endpoint agent
- Bounded to 30 days
- Out-of-scope list published
- Day 1 · Connect + inventoryread-only · about fifteen minutes
- Mapsystems → the frameworks that reach you
- Gatelive in your pipeline, override logged
- Day 30 · Recordyours either way · no obligation
Before you start
Two questions you cannot answer yet
They arrive from the board, the regulator, or an enterprise customer’s security questionnaire. Usually all three, within the same quarter.
“What AI are we running, and what is it touching?”
The honest answer in most organisations is a spreadsheet that was accurate once. Procurement knows the tools it bought. Nobody owns the AI features switched on inside tools you already licensed, or the agent a team stood up on a corporate card.
“If we were asked tomorrow, could we prove it was governed?”
An inventory is not evidence. Evidence is a record showing what was found, who owned it, which control it was assessed against, what was decided, who overrode it, and that none of that was edited afterwards.
Day 1
Fifteen minutes to your first real inventory
Discovery runs off the identity provider you already own. That is the whole integration for week one.
- Min 2 · App registrationMicrosoft Entra ID or Okta read-only scopes only
- Min 7 · Consentwe read sign-in activity and OAuth grants; we do not write to your directory
- Min 15 · Inventory landsthe usual blocker is calendar time with whoever owns the tenant
- Endpoint agent
- MDM push
- Network change
- Proxy re-route
- Data-warehouse build
- Platform-team project
Nothing installed on a laptop. Nothing pushed through your MDM. Nothing built before you see something useful.
Scope
What is in. What is deliberately out.
Both lists get the same space on this page, because the second one is what tells you whether the first one is true.
In scope · three things, in order
Shadow-AI discovery
The day-one inventory.
Policy-to-control mapping
Against the frameworks that actually reach you.
Promotion-gate enforcement
A hard gate at the release point.
Out of scope · stated up front
Deep and legacy telemetry connectors
Scoped separatelySplunk and comparable legacy integrations are real work. Pretending they fit inside 30 days would set the pilot up to fail.
Direct-to-runtime policy push
Roadmap · not shippedEnforcement emits a decision into your pipeline. It does not reach into your production runtime and change configuration on its own.
No autonomous kill switch
Your controls enforceWe decide and evidence; we do not stop your AI systems. A vendor promising to autonomously kill production AI for you is describing a change-management problem, not a feature.
Not a scanner of everything
Not sold as shippedAdversarial and red-team probing, membership-inference, model-inversion, extraction and training-data poisoning checks are not in the pilot. Some are roadmap.
Coverage is what routes through us
Gateway-routed onlyContinuous where AI traffic is routed through the gateway: enforcement is inline there and the audit trail is tamper-evident. Scanning across the rest of your estate is on-demand rather than always-on.
We sit on top of the tools you already run rather than replacing them. That boundary holds for the whole thirty days.
Day 30
Four artefacts. Yours either way.
If you do not continue with us, you still keep what the pilot produced. That is the point of bounding it.
- A defensible shadow-AI inventoryNot a survey response. Built from your own identity and consent records, with owners attached.
- Systems mapped to frameworks, gaps visibleEvery discovered system against the regimes that reach you, including the ones where the honest answer is "no control mapped yet".
- A working release gateLive in your pipeline, blocking on evidenced risk, with a logged human override path your engineers will actually accept.
- A tamper-evident recordDiscovery, risk, decision, override: hash-chained, so an auditor can verify after the fact that the record was not edited.
Low risk
Low risk, and specifically why
“Low risk” is a claim every vendor makes. Here is the version you can check against the scope: six checks, drawn on what we actually touch.
- Identity · read-only to startnothing we do in week one changes your environment
- Endpoints · no new agentso no rollout and no rollback
- Network · untouchedno proxy re-route, no change
- Budget · no fee, no purchase orderno budget line to defend before you can start
- Bounded scopewritten down before we begin, out-of-scope list attached
- Value on day onethe inventory lands before the gate work starts
- Candor about limits before you sign, not afterthis page is the evidence of that
Design Partner Programme
The pilot is free. Here is the whole of it.
The AI Governance Command Center is pre-GA, and we would rather build it against four regulated environments than a hundred opinions. That is the entire reason this costs nothing, and it is the whole arrangement, not the summary of a longer contract.
Fit check
Check the fit before you book
This is a self-qualifier, not a gate. If the first list does not describe you, the pilot will underdeliver, and we would rather you knew that now.
You need all three
Helpful, not required
Not sure which regimes reach you? The AI Risk Calculator takes eight questions and no email address.
Book
Bring your security lead. Thirty minutes.
A working session, not a pitch deck. We scope what discovery would actually reach in your environment, which frameworks apply, and whether a design-partner pilot makes sense at all. There is nothing to price: the pilot is free, and the thirty days end with no obligation on either side.
Booking opens our calendar in a new tab; pick any slot. Bring whoever owns your identity tenant. It shortens day one considerably.
- 1What discovery would actually reach in your environment
- 2Which frameworks apply
- 3Whether a design-partner pilot makes sense at all
Nothing to price. No obligation on either side at day thirty.
